Web Hack List

Collected research

One Scheme to Rule Them All: OAuth Account Takeover

Ostorlab: Mobile App Security Testing for Android and iOS

A malicious mobile app registers the custom URL scheme a legitimate app uses as its OAuth redirect_uri, so the authorization grant issued for that app's client_id is delivered to the attacker and the victim's account is taken over. Scheme conflicts are dodged by claiming the app's iOS scheme on Android or a loosely validated host, and consent is skipped via login_hint.

Record

Document
Ostorlab: Mobile App Security Testing for Android and iOS
Researcher
Mohamed Benchikh
Published by
Ostorlab
Date
Topic
Identity

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Mohamed Benchikh, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .